Paw & Story — Cookie Policy
Version 2.2 — Effective: 2026-09-02
The short version: Paw & Story sets no cookies. We load no analytics, no social buttons and no third-party scripts of any kind. What we keep in your browser is small: two strictly necessary entries that let you reopen and manage your own tribute, and — only if you arrive on a specially labelled link — a temporary note of which advert or link brought you here, whose copy in your browser disappears when you close the tab, and of which we also keep a record on our own server. There is also one advertising-related marker that is never written today, because no advertising pixel is switched on. This policy explains exactly what each of those is, and the two places where another company is involved.
1. Who is responsible
The data controller is Egységmester Kft., registered seat 2330 Dunaharaszti, Gyóni Géza köz 8., Hungary (company reg. no. 13-09-162959, registry court: Budapest Környéki Törvényszék Cégbírósága, EU VAT no. HU24291608). Contact: hello@pawandstory.com. For how we handle personal data more broadly, see our Privacy Policy.
2. What this policy covers
A cookie is a small text file a website stores in your browser so it can remember something between page loads. The ePrivacy rules cover not just cookies but any storing of or access to information on your device — including local storage. So this policy covers both, and it is local storage rather than cookies that we actually use.
3. Cookies we set: none
We set no cookies whatsoever on pawandstory.com — not for sessions, not for security, not for preferences, and not for measurement. Earlier versions of this policy described session, CSRF and analytics cookies; the Service does not set them, and we have corrected this page to say so.
4. What we do store: your tribute keys
When you create a tribute, we save an entry in your browser's local storage, named paw_owner_ followed by your project's number. It holds a random key that acts as proof that this browser is the one that created that tribute, so that only you can open it. Without it you would lose access to your own memorial page and downloads.
- It is strictly necessary to provide the service you asked for, which is why it is exempt from the consent requirement in Art. 5(3) of the ePrivacy Directive — and why we show no cookie banner.
- It contains no name, no email address and no tracking identifier, and it is never used to profile you or to follow you across websites.
- It stays in your browser until you clear your browser storage. It is not sent to any third party.
- If you clear it or switch browser, you lose the shortcut back into your tribute — write to hello@pawandstory.com and we will restore your access.
If your tribute has a memorial page, we save a second entry alongside the one above, named paw_memorial_ followed by that page's share address. It is written on your own delivery page — the page you reach through the link we email you after payment — and written again when you turn sharing on for that memorial page. It holds only the number of the tribute the address belongs to, so that when you later open your own memorial link in this browser, the page can recognise it as yours and show you the memories people have left there and your moderation controls. The page itself does not reveal that, on purpose — and the entry is never written for an ordinary visitor browsing a memorial page.
- It is strictly necessary in the same way and for the same reason as the key above, and it is why the page shows no cookie banner.
- It contains no name, no email address and no tracking identifier — a tribute number and nothing else — and it is never used to profile you or to follow you across websites.
- It stays in your browser until you clear your browser storage, it is not sent to any third party, and clearing it takes nothing away except the moderation controls on that page, which come back when you open the tribute again from your delivery link in this browser.
5. Which advert or link brought you here
Sometimes a link to Paw & Story carries small labels saying which advert or campaign it came from — things like utm_source, utm_medium, utm_campaign or a referrer code — or an advertising click identifier such as gclid, gbraid or wbraid (Google) or fbclid (Meta): a code the advertising platform puts on the link to identify that one click. If you arrive on such a link, we save those labels and that identifier in your browser's session storage, under the name fp_utm. Each value is cut off at 255 characters, only your first arrival is recorded, and our code also sends it to our own server on every page view, where we keep it in our database in the EU as a record of which advert or link brought the visit. Where that visit leads to a tribute or a purchase, the record is linked to that customer record.
- This entry is not strictly necessary to provide the service. It exists so we can tell which advert or link brought a visitor here.
- It holds only the labels and the click identifier from that one link — a Google gclid, gbraid or wbraid, or a Meta fbclid. It contains no name, no email address and nothing that tells us who you are: a click identifier is a code for one click, not for a person, and we have no means of our own to work out who you are from it. Today it is sent only to our own server and to no other company. The one circumstance that would change this is matching a purchase back to an advert click by sending the identifier to the advertising platform — if we ever start doing that, we will update this policy and state the legal basis before we do.
- It lives in session storage, so the copy in your browser is deleted automatically when you close the tab. The record we keep on our own server is not removed by closing the tab, but it can be erased on request — write to hello@pawandstory.com. If you never arrive on a labelled link or an advertising link, it is never written at all.
6. An advertising marker we may one day use — but do not today
Our code contains a small entry named paw_fb_purchase_ followed by your project's number, which a Meta (Facebook) advertising pixel would use to make sure a purchase is not counted twice. No such pixel is switched on — no pixel id is configured for this site — so this entry is never written today, and no Meta script loads on our pages. If we ever turn Meta advertising measurement on, we will ask for your consent first, and we will update this policy before we do so.
7. Stripe's cookies, on Stripe's page
When you pay, you are taken to a checkout page operated by Stripe Managed Payments (the seller and merchant of record is Sold through Link, LLC, a Stripe company; Stripe Payments Europe, Ltd. acts as the payment processor). Stripe sets its own cookies there to process the payment securely and to prevent fraud. Those are Stripe's cookies on Stripe's page, governed by Stripe's cookie and privacy notices, not ours. We do not embed Stripe scripts into our own pages to track you.
8. Error reports we receive (no cookies involved)
So that we can find and fix faults, your browser sends a report to our own error-monitoring server at errors-c7f31a.practicalapps.studio when something goes wrong, and for roughly one page view in ten. The report contains the address of the page and technical details of the error. It sets no cookie and reads nothing from your device; tokens, cookies, request contents and program variables are stripped out before it is sent, and we never record your screen. The server is operated by us, not by an outside analytics company. You can object to this processing at any time — see Section 7 of the Privacy Policy.
9. What we do NOT use
- No advertising, retargeting or conversion pixels are configured or active on our site — none loads and none measures you today. The advert click identifiers described in Section 5 are recorded by our own code on our own server, not by any advertising pixel.
- No cross-site, social-media or third-party tracking of any kind.
- No third-party analytics product.
- No externally hosted fonts, maps or embeds.
- We never sell your data.
10. How to control what is stored
You can clear or block site data — including local storage — in your browser settings at any time, and you can browse the public parts of the site with it blocked. Because the entry described in Section 4 is what proves a tribute is yours, blocking or clearing it will stop you reopening your tribute from that browser until we restore your access.
11. Changes
If this policy changes in a way that matters, we will post the new version here with a new effective date.